Wind River Support Network

HomeDefectsLIN1019-6138
Fixed

LIN1019-6138 : Security Advisory - qemu - CVE-2021-3416

Created: Feb 25, 2021    Updated: Apr 24, 2021
Resolved Date: Apr 24, 2021
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.

https://lists.gnu.org/archive/html/qemu-devel/2021-02/msg07431.html

CREATE(Triage):(User=admin) [CVE-2021-3416|https://nvd.nist.gov/vuln/detail/CVE-2021-3416]

CVEs


Live chat
Online